Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

OFAC vs OFSI: EAR99 determinations: what businesses miss

A technology exporter finalises a sale of what it classifies as EAR99 (items not listed on the Commerce Control List and therefore the lowest-risk export category under the US Export Administration Regulations) goods to a European buyer. The compliance team notes "EAR99 – no licence required" and closes the file. Six months later, the transaction triggers an enquiry from the Office of Foreign Assets Control. The export-control classification was entirely correct. The sanctions problem was not.

An EAR99 determination tells you nothing about OFAC obligations. It resolves only the export-licence question under the EAR administered by the Bureau of Industry and Security. OFAC's sanctions prohibitions run in parallel, are based on different authority, and apply regardless of a product's classification. The UK's Office of Financial Sanctions Implementation operates under its own statutory basis and its own ownership-and-control test – creating a second, independent layer of analysis that many businesses do not apply when they believe a product is "cleared" under the EAR.

This analysis sets out how EAR99 determinations work, where OFAC and OFSI diverge in their treatment of the same transaction, and what a cross-border business should do to avoid the gap between export classification and sanctions compliance.

What is an EAR99 determination, and what authority governs it?

An EAR99 determination is the conclusion that a specific item, software, or technology does not appear on the Commerce Control List and therefore carries no Export Control Classification Number requiring a licence for most destinations and end-uses. BIS administers the EAR under the authority of the Export Control Reform Act and the underlying statutory powers it inherited from earlier trade legislation. The determination is the output of a classification analysis, not a clearance certificate issued by any government body.

The classification process requires a business to work through the Commerce Control List methodically: first confirming the item's technical parameters against each entry, then establishing whether any applicable classification applies. If no entry matches, the item is EAR99 by exclusion. The process sounds mechanical. In practice, it is not. Dual-use characteristics – encryption functions embedded in an otherwise ordinary consumer product, for example – can bring an apparently simple item within a controlled category. A misclassification of a controlled item as EAR99 is an export-control violation independent of any sanctions issue.

What the EAR99 determination does not do is equally important. It does not screen the buyer, the end-user, or the transaction against OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the Entity List, or the Denied Persons List. It does not evaluate whether the transaction involves a country programme, a sectoral restriction, or a secondary-sanctions risk. The export-control analysis and the sanctions analysis are parallel obligations with separate legal bases. Completing one does not discharge the other.

How does OFAC's sanctions analysis apply to an EAR99 item?

OFAC's authority derives from the International Emergency Economic Powers Act and, for some programmes, the Trading with the Enemy Act. OFAC prohibitions attach to transactions, parties, and jurisdictions – not to the nature of the goods being shipped. A shipment of entirely uncontrolled paper could be a prohibited transaction if the buyer is an SDN or the destination falls within a comprehensive country programme. The product's EAR99 status is legally irrelevant to that analysis.

The practical consequence is that a business relying only on an EAR99 determination to clear a transaction is looking at the wrong question. The correct OFAC analysis requires: screening the buyer, the ultimate end-user, and all intermediate parties against the SDN List and applicable country-programme restrictions; applying the 50 percent rule (OFAC's rule that treats any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked, even if the entity is not itself listed); assessing whether sectoral sanctions apply to the transaction even absent a listed-person connection; and confirming that no general licence (a standing authorisation permitting a defined category of transactions without a separate application) is required for the activity.

In our experience, the error pattern is consistent. A company with a well-designed export-compliance programme – classification reviews, jurisdiction checks, denied-party screening of the immediate buyer – fails to apply the 50 percent rule to the buyer's ownership chain. The immediate buyer is clean. The buyer's majority shareholder is not. The EAR99 determination provided genuine comfort on the export-control side. It provided none on the sanctions side. Have you screened the ownership chain, or only the named counterparty?

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the ultimate end-user – can change the analysis significantly. For an assessment of your exposure under OFAC, contact Calder & Vance at info@caldervance.com.

Where does OFSI diverge from OFAC on the same transaction?

OFSI administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act and the relevant thematic sanctions regulations made under it. Its ownership-and-control test differs from OFAC's in a critical respect: where OFAC applies a mechanical ownership threshold of 50 percent or more, OFSI and the EU apply a test that includes both ownership and control. A non-listed entity can be caught by OFSI's rules even if no single listed person – or group of listed persons in aggregate – holds more than 50 percent of its shares, provided that a listed person exercises effective control over the entity.

This difference has direct consequences for a cross-border business that has applied OFAC's 50 percent rule and found no issue. The OFSI analysis must still be run independently. An intermediate holding structure that passes the OFAC test because aggregate listed ownership sits at 42 percent may fail the OFSI test if the listed minority shareholder controls the board, controls contractual approval rights, or otherwise directs the entity's activities. The control dimension is factual and requires documentary evidence: governance documents, shareholder agreements, board minutes, veto rights.

OFSI's enforcement posture has also shifted. OFSI now holds powers to impose civil monetary penalties on a strict-liability basis – meaning that a breach can be sanctioned without proof of knowledge or intent. The financial-sanctions licensing regime administered by OFSI also differs from OFAC's: a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) issued by OFSI does not authorise the same transaction under OFAC, and vice versa. A business with a valid OFSI licence for a particular transaction must still confirm its OFAC position separately.

We regularly advise businesses that have obtained OFSI licences and then discovered that the corresponding OFAC analysis was not carried out. The two regimes share similar policy aims but operate through distinct legal instruments, administered by separate authorities, with different procedural requirements and timelines. When OFAC and OFSI positions diverge, the stricter prohibition governs each jurisdiction – there is no harmonisation mechanism that automatically brings one regime into line with the other.

What does the EU position add, and how does it interact with OFAC and OFSI?

The EU's financial sanctions regime operates through Council regulations applicable in all EU member states. Like OFSI, the EU applies an ownership-and-control test that extends beyond the mechanical 50 percent threshold. An entity can be caught if it is "owned or controlled" by a designated person, and the EU's implementing guidance makes clear that control can arise through formal rights, informal influence, or economic dependence.

For a business with operations in the United Kingdom, the United States, and the EU, an EAR99 determination triggers three separate sanctions analyses – each run under a different legal authority, each with its own definitions, thresholds, and procedural requirements. A product that is uncontrolled under the EAR may still be the subject of separate EU export authorisation requirements under the EU dual-use regulation. The EU rules assess the nature of the end-user and the end-use, not only the technical classification of the goods. Where an EU member state maintains its own additional controls on a category of goods, those national measures apply in addition to the EU-level regime.

The interaction creates a compound-compliance problem. A company that completes the EAR99 determination, screens under OFAC, and screens under OFSI has still not necessarily completed its EU analysis – particularly if the shipment transits EU territory or involves an EU-based party in the transaction chain. Businesses sometimes assume that a clean OFAC determination is the highest standard; the EU and OFSI positions can in practice be broader, depending on the specific designation and the control test applied.

What are the risk flags a business should identify before relying on an EAR99 determination?

An EAR99 determination does not eliminate risk; it resolves one specific compliance question. Several risk flags indicate that the broader sanctions analysis requires particular care, regardless of the product's classification.

  • Layered ownership structures. Where the buyer or end-user sits within a holding group with multiple layers of intermediate companies, the 50 percent rule and the OFSI/EU control tests must be applied at each level. Beneficial-ownership data may not be current or complete.
  • Financial-institution involvement. Where a bank, correspondent bank, or payment processor is involved in the transaction, that institution applies its own screening. A transaction that the exporter has cleared may be blocked at the payment stage if the financial institution identifies a connection that the exporter missed.
  • Dual-use characteristics at the margin. A product classified as EAR99 after a careful analysis may still attract scrutiny if it has characteristics that are adjacent to controlled categories. Enforcement agencies review classification methodology, not just the output.
  • Third-country re-export risk. An EAR99 item shipped to a clean buyer in a permitted jurisdiction can still generate liability if the exporter has reason to know the goods will be re-exported to a sanctioned destination or end-user. Knowledge and red-flag awareness are part of the OFAC and BIS analysis.
  • Sanctions-designated intermediaries. Freight forwarders, logistics providers, and financial intermediaries in the transaction chain can themselves be designated. Screening the ultimate buyer does not discharge the obligation to screen all parties involved in the transaction.

If a transaction has already been flagged, or a filing has been refused, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

What a business commonly misunderstands about EAR99 determinations and sanctions compliance

The most persistent myth in cross-border trade compliance is that "EAR99" is a clearance. Businesses that invest in accurate export-classification programmes sometimes treat a confirmed EAR99 determination as the end of the compliance analysis. It is not. It is the conclusion of one strand of a multi-strand review.

A second misunderstanding concerns the direction of stricter prohibition. Where OFAC and OFSI diverge – for example, on the control test for non-listed entities – a business sometimes assumes that compliance with the more familiar regime satisfies both. It does not. Each regime must be satisfied independently on its own terms. A valid authorisation under one regime does not extend to another. This is not a technicality; it is a structural feature of how multinational sanctions regimes operate.

A third error is the assumption that financial sanctions are only a concern for financial institutions. Every business involved in international trade – exporters, manufacturers, distributors, logistics providers, professional-services firms – is subject to the sanctions prohibitions of the regimes applicable to its operations. The obligation to screen counterparties, apply the relevant ownership-and-control tests, and maintain records is not limited to banks. In our cross-border practice, we see this misunderstanding most often in manufacturing and technology-distribution businesses that have strong export-compliance programmes but have not integrated sanctions screening into the same workflow.

A fourth misapprehension concerns timing. Businesses sometimes believe that if a transaction has been executed – goods shipped, payment received – the compliance window has closed. That is incorrect. Many regimes impose continuing obligations, including obligations to report discovered violations, to maintain transaction records for extended periods, and to take remedial steps when a breach is identified. A VSD (voluntary self-disclosure to a regulator) may be available and, under the applicable regime's enforcement guidance, may significantly affect the outcome of any subsequent enforcement action. The window for a VSD is not indefinite, and the analysis of whether and how to make one requires legal advice on the specific facts.

What a cross-border business should do: a practical decision sequence

A structured approach to EAR99 compliance does not require parallel bureaucracies. It requires a clear sequencing of the relevant checks, with ownership of each strand assigned to a specific process.

  1. Confirm the export-control classification. Verify the EAR99 determination against the current Commerce Control List, including any recent changes to controlled categories. For items with dual-use characteristics at the margin, consider whether a commodity classification request to BIS is appropriate.
  2. Screen all transaction parties under OFAC. Screen the buyer, the end-user, and every known intermediary against the SDN List and applicable country-programme restrictions. Apply the 50 percent rule to the buyer's full ownership chain, not only the immediate counterparty.
  3. Apply the OFSI control test independently. For any transaction with a UK nexus – UK parties, UK-based payment processors, goods transiting UK territory – run the OFSI analysis separately. The control test requires documentary evidence of governance and decision-making authority at each relevant level of the ownership chain.
  4. Assess EU obligations where relevant. For transactions with an EU nexus, apply the EU ownership-and-control test and confirm whether EU dual-use authorisation requirements apply to the goods, irrespective of the EAR99 classification.
  5. Document the analysis. Record the classification basis, the screening methodology, the ownership-chain analysis, and the conclusion on each strand. Records should be maintained for the period required by the applicable regime – verify the current requirement before finalising the programme.
  6. Build in a red-flag review. Before execution, confirm that no red flags have emerged: unusual payment routing, requests to omit end-user information, inconsistent end-use statements, or changes to the delivery destination. Red-flag indicators are relevant to both BIS and OFAC analyses.
  7. Establish a remediation protocol. Define in advance what steps the business will take if a post-execution review identifies a potential issue: who is notified, who conducts the internal review, and who advises on whether a VSD is appropriate.

In a recent matter, a manufacturing business with an established export-compliance programme identified, during a post-acquisition review of the acquired entity's transactions, a series of shipments classified as EAR99 to a buyer whose majority shareholder had been added to the SDN List before the shipment date. The acquired entity's compliance team had confirmed the EAR99 classification and screened the immediate buyer, which was not listed. The 50 percent rule had not been applied to the ownership chain. We scoped the apparent violations, assessed the disclosure options under the applicable regime's voluntary self-disclosure process, and prepared the compliance package. The matter proceeded through the enforcement process, and the business was able to demonstrate a prompt, well-evidenced remedial response.

Related practices

Frequently asked questions

Where do the regimes diverge on EAR99 determinations?
The EAR99 determination is a US export-control concept with no direct equivalent in UK or EU law. Under OFAC, the product's classification is irrelevant to the sanctions analysis; what matters is the identity of the parties and the jurisdiction of the transaction. OFSI and the EU add a control-based test for non-listed entities that is broader than OFAC's mechanical 50 percent ownership threshold. A transaction that passes OFAC's ownership test may still be caught by OFSI's or the EU's control test, and vice versa. The three regimes must be assessed independently.
Which regime is stricter on EAR99 determinations?
No single regime is uniformly stricter. OFAC's 50 percent rule is mechanical and catches entities through aggregate ownership without requiring evidence of control. OFSI and the EU can capture entities with lower ownership percentages if a listed person exercises control, making their tests potentially broader for certain ownership structures. For a comprehensive programme, each regime must be satisfied on its own terms. Where the regimes diverge, the stricter prohibition governs in each jurisdiction separately – there is no shared hierarchy.
What should a cross-border business do about EAR99 determinations?
Confirm the EAR99 classification is accurate, then run the OFAC, OFSI, and EU sanctions analyses as separate, sequential steps. Apply the relevant ownership-and-control test at each level of the counterparty's ownership chain – not only to the immediate buyer. Document each strand of the analysis. Maintain records for the period required under each applicable regime. If a potential issue is identified after execution, seek legal advice promptly on whether a voluntary self-disclosure is appropriate. An integrated compliance workflow, rather than a siloed export-classification process, is the effective standard.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.